The OPC XML-DA server statistics page of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) stores and renders the User-Agent header without neutralisation (CWE-79, CWE-116). An unauthenticated remote attacker can execute arbitrary JavaScript in an administrator’s browser via a crafted User-Agent header in a POST /da request, enabling session hijacking, credential theft and device reconfiguration.